Top Spam WordPress Plugins
67 indexed plugins
Plugins
67
Active Installs
8m+
Average Score
56
Audited
66
Top Scores
| Rank | Plugin | Score | Errors | Warnings | Installs | Added | Updated | Top Issue |
|---|---|---|---|---|---|---|---|---|
| #1 | Dam Spam | 100 | 1 | 1k+ | unexpected markdown file | |||
| #2 | Simply Disable Comments | 100 | 0 | 6k+ | No open findings | |||
| #3 | Block List Updater | 99 | 1 | 0 | 4k+ | outdated tested upto header | ||
| #4 | Block Specific Spam Woo Orders | 99 | 1 | 4 | 1k+ | Non-prefixed hook name | ||
| #5 | Stop WP Emails Going to Spam | 99 | 1 | 3 | 10k+ | trademarked term | ||
| #6 | Anti-Spambot | 97 | 3 | 2 | 600 | Missing direct file access protection | ||
| #7 | Gravity Forms Zero Spam | 94 | 4 | 9 | 100k+ | trademarked term | ||
| #8 | Stop Spammers Classic | 94 | 185 | 1 | 30k+ | wp function not compatible with requires wp | ||
| #9 | Sucuri Security – Auditing, Malware Scanner and Security Hardening | 94 | 52 | 5 | 600k+ | Missing direct file access protection | ||
| #10 | Simple Honeypot for Contact Form 7 | 91 | 1 | 6 | 500 | Missing nonce verification | ||
| #11 | LH Multipart Email | 91 | 4 | 5 | 600 | Non-prefixed hook name | ||
| #12 | Disable WP Registration Page | 89 | 4 | 9 | 2k+ | trademarked term | ||
| #13 | WP fail2ban Add-on for Contact Form 7 | 85 | 10 | 18 | 800 | Non-prefixed constant | ||
| #14 | WP fail2ban Add-on for Gravity Forms | 85 | 10 | 18 | 600 | Non-prefixed constant | ||
| #15 | Hizzle CAPTCHA – Protect your forms from spam | 80 | 4 | 27 | 500 | Non-prefixed global variable | ||
| #16 | Image Captcha For Gravity Forms | 80 | 20 | 10 | 400 | Text Domain Mismatch | ||
| #17 | Honeypot Plus for Contact Form 7 | 77 | 3 | 17 | 700 | Missing nonce verification | ||
| #18 | Bulk Comments Management | 75 | 6 | 25 | 700 | Direct Query | ||
| #19 | En Spam | 75 | 21 | 6 | 500 | wp function not compatible with requires wp | ||
| #20 | Honeypot Anti Spam for Forminator Forms | 75 | 4 | 7 | 1k+ | Missing nonce verification | ||
| #21 | Formidable Honeypot | 74 | 10 | 6 | 400 | Text Domain Mismatch | ||
| #22 | Comment Form CSRF Protection | 70 | 7 | 10 | 500 | Request data is not unslashed | ||
| #23 | Simple Login Captcha | 70 | 20 | 19 | 10k+ | date date | ||
| #24 | User Last Login | 65 | 27 | 5 | 600 | Output is not escaped | ||
| #25 | Comment Blacklist Manager | 64 | 14 | 8 | 600 | Output is not escaped | ||
| #26 | Kama SpamBlock | 64 | 29 | 7 | 5k+ | Short PHP open tag found | ||
| #27 | Constructor for SiteOrigin | 61 | 29 | 6 | 600 | Output is not escaped | ||
| #28 | Add Google re captcha in WordPress Forms | 59 | 16 | 16 | 500 | Output is not escaped | ||
| #29 | Delete Pending Comments | 57 | 16 | 11 | 10k+ | Unsafe printing function | ||
| #30 | Anti-Captcha (anti-spam botblocker) | 56 | 23 | 26 | 1k+ | rand mt rand | ||
| #31 | Batch Comment Spam Deletion | 46 | 22 | 15 | 1k+ | Nonce verification recommended | ||
| #32 | Smart Attachment Page Remove | 44 | 82 | 3 | 900 | Output is not escaped | ||
| #33 | ReCaptcha v2 for Contact Form 7 | 44 | 12 | 30 | 200k+ | Nonce verification recommended | ||
| #34 | Anti-spam Reloaded | 43 | 19 | 19 | 2k+ | Output is not escaped | ||
| #35 | Rut Chileno con Validación para WooCommerce | 43 | 35 | 16 | 1k+ | Text Domain Mismatch | ||
| #36 | Uber reCaptcha | 43 | 129 | 45 | 1k+ | Text Domain Mismatch | ||
| #37 | Comment Blacklist Updater | 42 | 45 | 15 | 1k+ | Output is not escaped | ||
| #38 | hCaptcha for WP | 42 | 115 | 18 | 70k+ | Exception output is not escaped | ||
| #39 | reCAPTCHA for WooCommerce | 42 | 80 | 31 | 40k+ | Output is not escaped | ||
| #40 | Antispam | 41 | 11 | 41 | 400 | Missing nonce verification | ||
| #41 | Email Address Encoder | 41 | 109 | 8 | 100k+ | wp function not compatible with requires wp | ||
| #42 | Image CAPTCHA for Contact Form 7 and WPForms by HookAndHook (DSGVO/GDPR) | 39 | 28 | 45 | 80k+ | Missing nonce verification | ||
| #43 | Cookies for Comments | 39 | 22 | 29 | 20k+ | Input is not validated | ||
| #44 | Analytics Spam Blocker | 37 | 76 | 22 | 800 | Unsafe printing function | ||
| #45 | Exploit Scanner | 37 | 25 | 130 | 8k+ | Non-prefixed global variable | ||
| #46 | Spam Destroyer | 37 | 63 | 43 | 6k+ | rand rand | ||
| #47 | Akismet Anti-spam: Spam Protection | 35 | 33 | 99 | 6m+ | Non-prefixed global variable | ||
| #48 | Block Comment Spam Bots | 35 | 31 | 17 | 800 | Output is not escaped | ||
| #49 | CM E-Mail Blacklist – Simple email filtering for safer registration | 35 | 269 | 205 | 800 | Output is not escaped | ||
| #50 | Friendly Captcha for WordPress | 35 | 192 | 62 | 9k+ | Output is not escaped |